4 ms·
Internal DHS red team sounds like one hell of a job if they include physical security checks (aka “Airport Security”) in the list of things the red team is allo
by techdragon 3y ago
Internal DHS red team sounds like one hell of a job if they include physical security checks (aka “Airport Security”) in the list of things the red team is allowed to attempt to bypass/exploit … like this could be a boring government desk job … or… it could be professional heist movie LARPing with all the fun of sneaking past the real security stuff but none of the risk of getting thrown into a jail cell to rot… and the follow on question is how they monitor and supervise this, like if it is physical pen testing the airport security line, do they carry any sort of documentation to stop things getting out of hand or is it entirely up to their superiors up the chain to stop them winding up in jail for real…
I’m expecting it isn’t as exciting as it could be, but I really want to know more.
- kmoser 3y agoSeveral decades ago I was hired by a multinational bank to do software development, and one of my first tasks was to glean as much information as I could about one of the competitors' ATMs. My manager gave me a letter (on company letterhead) to carry with his contact info that described what I was doing, in the event security stopped me for spending an inordinate amount of time going through as many screens on the ATM as I could and writing down things about the UI. (Spoiler alert: nobody stopped me.) I'm not an expert in airport security at all, but I'd bet dollars to donuts that anybody doing physical pen testing of that type will carry documentation describing who they are, who they work for, and what they are doing.
- techdragon 3y agoSee this was my first thought but then it occurred to me that they’re trying to bypass people who are meant to be inspecting your stuff, does part of the job become “sneak past with this bit of paper” or do they carry nothing official on them to make the test more authentic, having paper documents risks biases towards staff procedures that would catch people with the document and thus end any pen testing attempts with potentially only a perceived improvement to security when they could be failing to catch people with usb drives or whatever else they are meant to be on the lookout for…
- kmoser 3y agoI think your concerns are unfounded. TSA doesn't generally sift through every bit of paper in your possession, nor do they really care what's written on any of the paper you're carrying since it's unlikely to be a threat.
- owlbite 3y agoI'd be somewhat concerned about an overzealous officer with a gun who "stops" me before I can pull out the paperwork.
- mike_d 3y agoI have done physical security red teams. It is 98% paperwork and planning that lets you do the 2% fun stuff. You carry a "get out of jail free card" (basic example below) which needs to be signed by someone high enough up to be able to authorize the work you are doing. I also request that it include contact info for at least 4 people who are aware of the testing and will answer their phone. Depending on the type of engagement and location I will sometimes notify friends in law enforcement ahead of time. https://www.netspi.com/wp-content/uploads/2018/02/Physical-Penetration-Testing-Authorization-Sample.png https://www.netspi.com/wp-content/uploads/2018/02/Physical-P...